Wato Docs
Connectors

Approval

Approve connectors for the workspace or specific teams, and govern which tools each team and role can use.

Connector access is governed in two layers: approving a connector for a team or the whole org, and controlling which tools within it are allowed.

Approve connectors

Org admins (or holders of tools:manage) manage approvals at Settings → Connectors.

  • Marketplace — connectors not yet approved. Approve one for:
    • Org-wide — available to every team.
    • Specific teams — installed for the teams you choose.
  • Approved MCPs — connectors already assigned, with the teams (or org-wide) they're assigned to. You can change scope or revoke here.
  • Requests — when a member requests a connector, it appears here to approve or reject.

Approving a connector installs it for the chosen scope and seeds its tool catalog.

Govern tool access

Approving a connector doesn't have to mean allowing every tool inside it. On a team's connector page, set the tool-access policy:

  • Mode
    • all_tools — every tool is allowed unless explicitly denied.
    • selected_tools — only explicitly allowed tools are usable.
  • Rules — allow or deny specific tools, scoped to a team role (member or team_admin) or an individual user.

This lets you, for example, allow a team to read CRM records while blocking tools that write or change admin settings.

Why this matters

MCP tools can read data, write records, trigger actions, or reach sensitive systems. Scoping access by connector, tool, role, and user keeps agent capabilities aligned with policy.

Who can do what

ActionRequired access
Approve / revoke connectorsOrg admin or tools:manage.
Configure a connector's credentialstools:manage or team admin.
Set a team's tool-access policytools:manage or team admin.
Request a connectorAny team member.

On this page